<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CheckPoint, Azure, Scaleset - not all traffic forwarded. in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158158#M819</link>
    <description>&lt;P&gt;Hi, I have a very strange issue with a scaleset in Azure. I have implemented these several times before, pretty much the same way, but I have never had this problem before.&lt;/P&gt;
&lt;P&gt;The setup is as of now pretty simple, I have the scaleset up n running in a VNET that also has a VirtualNetworkGateway wtih a route based vpn to onprem. And there is another VNET peered in, that has UDR's pointing it to the internal load balancer fo the scaleset.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The thing is - near everything works:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;- I can ping both ways (from onprem serv to azure server)&lt;/LI&gt;
&lt;LI&gt;-Run SSH from onprem to a server in the peered vnet..&lt;/LI&gt;
&lt;LI&gt;- RDP works same way..&lt;/LI&gt;
&lt;LI&gt;Traffic is inspected by firewall and flowing normal. (ccap verifies this, I have traffic entering and exiting on the internal nic)&lt;/LI&gt;
&lt;LI&gt;Internet traffic from the peered vnet hits mye scaleset, natted, and works fine. Ping to internet, works fin.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;BR /&gt;But, for some reason - I am unable to getanything but the standard ports to work. :&lt;/P&gt;
&lt;P&gt;As an example (this is the same for lots of other ports): I try to open port tcp1433 from a server in the peered vnet - the traffic enters my scaleset, is processed and then sent out towards the virtual network gateway. And then it is gone.... I am unable to see it entering the onprem checkpoint at all.... its just gone.&amp;nbsp; If I did tcp3389 or tc22 from, and to, the same IP's... it works..&lt;/P&gt;
&lt;P&gt;So I just have an issue with some/lots of ports not working.. I have checked all NSG's and all policies, run debug.. It just seems to be lost in Azure somewhere ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have anyone had this issue ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2022 12:49:21 GMT</pubDate>
    <dc:creator>vinceneil666</dc:creator>
    <dc:date>2022-09-27T12:49:21Z</dc:date>
    <item>
      <title>CheckPoint, Azure, Scaleset - not all traffic forwarded.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158158#M819</link>
      <description>&lt;P&gt;Hi, I have a very strange issue with a scaleset in Azure. I have implemented these several times before, pretty much the same way, but I have never had this problem before.&lt;/P&gt;
&lt;P&gt;The setup is as of now pretty simple, I have the scaleset up n running in a VNET that also has a VirtualNetworkGateway wtih a route based vpn to onprem. And there is another VNET peered in, that has UDR's pointing it to the internal load balancer fo the scaleset.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The thing is - near everything works:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;- I can ping both ways (from onprem serv to azure server)&lt;/LI&gt;
&lt;LI&gt;-Run SSH from onprem to a server in the peered vnet..&lt;/LI&gt;
&lt;LI&gt;- RDP works same way..&lt;/LI&gt;
&lt;LI&gt;Traffic is inspected by firewall and flowing normal. (ccap verifies this, I have traffic entering and exiting on the internal nic)&lt;/LI&gt;
&lt;LI&gt;Internet traffic from the peered vnet hits mye scaleset, natted, and works fine. Ping to internet, works fin.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;BR /&gt;But, for some reason - I am unable to getanything but the standard ports to work. :&lt;/P&gt;
&lt;P&gt;As an example (this is the same for lots of other ports): I try to open port tcp1433 from a server in the peered vnet - the traffic enters my scaleset, is processed and then sent out towards the virtual network gateway. And then it is gone.... I am unable to see it entering the onprem checkpoint at all.... its just gone.&amp;nbsp; If I did tcp3389 or tc22 from, and to, the same IP's... it works..&lt;/P&gt;
&lt;P&gt;So I just have an issue with some/lots of ports not working.. I have checked all NSG's and all policies, run debug.. It just seems to be lost in Azure somewhere ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have anyone had this issue ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 12:49:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158158#M819</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-09-27T12:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint, Azure, Scaleset - not all traffic forwarded.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158447#M820</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/12733"&gt;@Shay_Levin&lt;/a&gt;&amp;nbsp;can you pelase assist?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 13:07:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158447#M820</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-29T13:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint, Azure, Scaleset - not all traffic forwarded.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158474#M821</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the routing on the Azure VPN GW , towards your peered vnet subnet ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The next hop of your Azure VPN GW towards your peered vnet subnet , should point on the front NLB&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 17:53:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158474#M821</guid>
      <dc:creator>Shay_Levin</dc:creator>
      <dc:date>2022-09-29T17:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint, Azure, Scaleset - not all traffic forwarded.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158475#M822</link>
      <description>&lt;P&gt;To the front NLB ? - I have a routing table attached to mye virt net gw pointing towards the inside / private load balancer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 17:56:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158475#M822</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-09-29T17:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint, Azure, Scaleset - not all traffic forwarded.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158476#M823</link>
      <description>&lt;P&gt;I have never tested a scenario in which you place the VPN GW inside the CloudGuard vNet&lt;/P&gt;
&lt;P&gt;Why not to set a dedicated vNet to the Azure VPN Gateway and connect it with peering to the CloudGuard vNet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 19:29:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158476#M823</guid>
      <dc:creator>Shay_Levin</dc:creator>
      <dc:date>2022-09-29T19:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint, Azure, Scaleset - not all traffic forwarded.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158980#M824</link>
      <description>&lt;P&gt;Yeah - I could do that, but I cant see that really helping me out, it will pretty much change a bit on how I do my routing - and my routing is working fine. I usually see this setup at most of my customers - the vpn gateway on the same vnet as the CheckPoint scale set / or just a "regular Cloudguard fw.&lt;/P&gt;
&lt;DIV id="tinyMceEditor_5215cc34d15cf0vinceneil666_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="issue2.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18058i7977ECAFD027C5D9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="issue2.JPG" alt="issue2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This is the log, this is me running telnet on different ports from one of the CheckPoints in Azure. The thing I want to see here is of course the DECRYPT icon, as seen on line-3 from the top. I have tried the same test with the traffic beeing allowed on the on-prem firewall to..same issue..&lt;/P&gt;
&lt;P&gt;If I telnet on port tcp3389 - the traffic goes over the tunnel and is decrypted.&lt;/P&gt;
&lt;P&gt;If I telnet on tcp22 or tcp1433&amp;nbsp; (or tcp 6566,,tcp6666, tcp9189...etc etc) it do not seem to hit the tunnel at all... there is no decrypt. Same ip used for src and dest in all tests.&lt;/P&gt;
&lt;P&gt;I have tried editing the NSG to any any, I have removed the NSG completley. I have done /32 routes in the UDR - done /24 and /8's. But no go....&lt;/P&gt;
&lt;P&gt;The very very weird thing, is that traffic FROM on-prem, TO the example server in Azure - works fine..all ports works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 08:53:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/158980#M824</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2022-10-07T08:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint, Azure, Scaleset - not all traffic forwarded.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/159119#M825</link>
      <description>&lt;P&gt;Just to try to understand where the problem is , what about create a VM in the Cloudguard vNet, external subnet&amp;nbsp; , and try to open connection from that vm to the on prem server on different ports ( the cloudguard network external subnet needs to be part of the encryption domain in that case)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can do the test&amp;nbsp; form the cloudguard gw as well , For eliminate other potential issues , do it from a vm will be better.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 08:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Azure-Scaleset-not-all-traffic-forwarded/m-p/159119#M825</guid>
      <dc:creator>Shay_Levin</dc:creator>
      <dc:date>2022-10-10T08:13:02Z</dc:date>
    </item>
  </channel>
</rss>

